PT-2026-93654 · Linux · Linux Kernel
CVE-2026-90013
·
Published
2026-09-16
·
Updated
2026-09-25
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A use-after-free condition exists in the tracing component. This occurs because options files do not take a
trace array reference for the options they represent. If one task opens one of these files while another task removes the associated instance, the options descriptor currently in use may be freed, leading to a kernel crash. The system uses the trace flags index array to map flags to the trace array descriptor via the inode->i private pointer. To resolve this, a helper function trace array options get() was introduced to iterate through the ftrace trace arrays list under the trace types lock to properly increment the trace array reference.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel